# CVE-2026-30903

## Summary

- **CVE ID:** CVE-2026-30903
- **Severity:** CRITICAL
- **CVSS Score:** 9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
- **CWE:** CWE-73
- **Published:** Mar 11, 2026
- **Last Modified:** Mar 12, 2026

## Description

External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via network access.

## Affected Products

- Zoom Communications — Zoom Workplace (see references)

## References

- [CNA](https://www.zoom.com/en/trust/security-bulletin/zsb-26005)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.33%
- **EPSS Percentile:** 25.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._